AUGUST 24, 2026
Live Feed
Back to database
Case File

CVE-2026-16048

MEDIUM · CVSS 6.3 EPSS 0.15%

Source: NVD + CISA KEV + EPSS · Published 2026-08-17 · Last synced 2026-08-24

CyberRota Analysis

AI-Generated

Mattermost versions 11.8.x up to 11.8.2, 11.7.x up to 11.7.6, and 10.11.x up to 10.11.21 have a vulnerability that allows channel administrators to improperly assign elevated permissions through the channel member roles API. This could lead to unauthorized access and manipulation of channel settings, potentially compromising the integrity of channel data. Organizations using these versions should prioritize patching to mitigate the risk of privilege escalation.

CVE
CVE-2026-16048
Severity
MEDIUM
CVSS
6.3
EPSS
0.15%

Original NVD Description

Mattermost versions 11.8.x <= 11.8.2, 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 fail to restrict channel member role assignment to channel-scoped roles which allows a channel administrator to gain additional channel permissions via the channel member roles API.. Mattermost Advisory ID: MMSA-2026-00697

Related CVEs

Other vulnerabilities affecting the same vendor(s)